2026 CVE Vulnerabilities

53,163 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2738MEDIUM5.6Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packet...
CVE-2026-27440MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ...
CVE-2026-27387MEDIUM5.4Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configu...
CVE-2026-27368MEDIUM5.3Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd comi...
CVE-2026-27360MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Galler...
CVE-2026-27328MEDIUM5.3Missing Authorization vulnerability in DevsBlink EduBlink edublink allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-27327MEDIUM4.3Missing Authorization vulnerability in YayCommerce YayMail yaymail allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-27014MEDIUM5.5NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOff...
CVE-2026-26312MEDIUM6.5Stalwart is a mail and collaboration server. A denial-of-service vulnerability exists in Stalwart Mail Server versions 0...
CVE-2026-26282MEDIUM6.6NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an ou...
CVE-2026-27013MEDIUM6.1Fabric.js is a Javascript HTML5 canvas library. Prior to version 7.2.0, Fabric.js applies `escapeXml()` to text content ...
CVE-2026-26203MEDIUM6.5PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer und...
CVE-2026-26193MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6....
CVE-2026-26192MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7....
CVE-2026-27474MEDIUM6.1SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8...
CVE-2026-27473MEDIUM6.4SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC out...
CVE-2026-27472MEDIUM5.3SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing...
CVE-2026-26059MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated u...
CVE-2026-23621MEDIUM5.3GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the L...
CVE-2026-2817MEDIUM4.8Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directorie...
CVE-2026-2243MEDIUM5.1A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially ...
CVE-2026-23620MEDIUM5.3GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListSe...
CVE-2026-23619MEDIUM5.4GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains se...
CVE-2026-23618MEDIUM5.4GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che...
CVE-2026-23617MEDIUM5.4GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now